POSTER: A Proactive Cloud-Based Cross-Reference Forensic Framework

被引:3
作者
Liu Zhenbang [1 ]
Zou Hengming [1 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Software, Shanghai, Peoples R China
来源
CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2014年
关键词
proactive forensics; evidence collection; intrusion detection; security monitoring; cloud computing; Microsoft Azure;
D O I
10.1145/2660267.2662355
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Traditional computer forensic tools suffer from several drawbacks: 1) information recorded by the operating system and application may not be enough for performing exact forensics, because such information is not tailored for forensic purpose; 2) evidence extraction is based on single computer; 3) evidence is vulnerable to be tampered; 4) volatile yet important evidence may not be recorded for forensic analysis. To overcome these limitations, this paper proposes a cloud-based proactive forensics framework to record state information across a set of computers (such as the cluster of computers that consist a cloud) for cross forensic analysis. Our forensic framework is built on Microsoft Azure and can be scaled easily to accommodate the increase or decrease of forensic targets. The information recorded by our proposed forensics framework may be volatile and the recording frequency can be customized. When a digital crime occurs, there is no need to speculate what happened, instead we can analyze and cross reference the recorded information to reconstruct the events occurred. We have conducted an experiment to assess the feasibility of our framework and found the result to be satisfactory.
引用
收藏
页码:1475 / 1477
页数:3
相关论文
共 7 条